Field Guide to AI, Security and Cybercrime

BragJack: How a Browser Extension Hijacks Your AI Assistant's Trust

A malicious browser extension can impersonate the trusted channel between your AI assistant and its vendor, gaining its elevated privileges.

Field Guide to AI, Security and Cybercrime·Abdolmadjid Masoomi·4 October 2026·6 min read

The BragJack attack exploits the trust model of browser-based AI assistants. A malicious extension with common permissions intercepts communication to the vendor's origin, hijacking the agent's identity and privileges. You must audit extensions, update browsers, and consider disabling these assistants on sensitive devices.

You assume your browser's built-in AI assistant, like Copilot in Edge or Gemini Live in Chrome, has a secure, direct line to its maker. The assistant appears as a native feature, operating with a level of trust you grant the browser itself. The real risk is that this trusted channel can be impersonated by any extension you install. The BragJack attack demonstrates this precisely: a malicious extension hijacks the AI agent's identity, inheriting all its privileges to act on your behalf. This is not a flaw in the AI model but a failure in the agent's foundational trust model.

The extension is the man-in-the-middle

Browser extensions operate with significant power. As detailed in what your browser extension can see, common permissions like contentScripts and the declarativeNetRequest API allow an extension to read, modify, and block any web request. An AI assistant in your browser is not a magical entity; it is a web application. It communicates with its vendor's origin—copilot.microsoft.com or gemini.google.com—to receive instructions, process your queries, and access its capabilities.

A malicious extension configures itself to intercept requests to these specific origins. When your AI assistant tries to phone home, the extension steps in. It can present a forged response from the vendor or inject its own instructions into the legitimate traffic stream. The AI agent, designed to trust its designated origin, cannot tell the difference. The extension becomes a perfect man-in-the-middle, not for your data, but for the agent's command-and-control channel.

Hijacking the agent's trust model

The core of the attack is identity theft at the agent level. The AI assistant possesses an aggregated identity: it holds the permissions and access rights granted to it, which are often substantial. This could include reading your open tabs, analysing documents you provide, or using connected services. The OWASP list for agentic applications calls this "Identity and Privilege Abuse," where an attacker exploits inherited credentials.

When the extension impersonates the trusted origin, it hijacks this entire identity. The agent now takes its marching orders from the attacker. The attacker does not need to steal your login cookie or password; they simply tell the agent what to do, and the agent obeys, believing the commands come from its legitimate controller. This turns a low-privilege extension into a high-privilege actor, capable of executing the kinds of excessive agency that make AI agents dangerous.

Where you are exposed

This attack specifically affects the AI assistants built into Chromium-based browsers. Researchers disclosed that it impacted Google Chrome with Gemini Live, Microsoft Edge with Copilot, Opera, and the Perplexity and Claude browser extensions. The vulnerability existed because these agents relied on a web-based trust channel that extensions had the power to intercept. It is a classic case of a strong security model being undermined by a weaker, more permissive one—the extension ecosystem.

Your exposure begins the moment you install an extension from an untrusted source. The extension does not need to be obviously malicious; it could be a useful tool that was later sold or compromised. Its listing in the store would request common, seemingly benign permissions to "read and change data on websites," a request millions of users approve without a second thought. This creates a widespread attack surface, turning any compromised extension into a potential backdoor to your AI agent.

From interception to exploitation

Once the channel is hijacked, the attacker can issue any instruction the agent is capable of following. This is where the attack merges with other agentic risks. The attacker could perform a direct prompt injection, ordering the agent to summarise sensitive data and then encode it in a seemingly innocent response. They could force the agent to make unauthorized changes to your documents or emails if you have those integrations active.

More subtly, the attacker could use this channel to poison the agent's understanding over time, a form of memory poisoning. They could slowly alter the system prompts or contextual information the agent receives from its vendor, subtly shifting its behaviour to serve a long-term goal. This turns a one-time interception into a persistent compromise of the agent's logic, making it a new kind of insider threat that is incredibly difficult to detect.

How to defend your browser and agent

The primary defence is to regain control over the extension ecosystem. In an enterprise, this means using group policy to strictly limit which extensions can be installed, locking down the allow list to only verified, essential tools. For individual users, you must regularly audit your extensions and remove any that are not absolutely necessary, especially those with broad site-access permissions.

The most direct action is to update your browser. Patches were issued for Edge and Chrome to close this specific vulnerability. Ensure automatic updates are enabled. For devices handling highly sensitive information, consider disabling the built-in AI assistant entirely. The convenience is not worth the risk if that device is a target. The principle of least privilege applies here: if you do not need an agent with broad access, do not activate it.

Finally, recognise that browser-based AI agents operate in a hostile environment. You should treat them with the same caution as any other application that handles your data. Do not ask them to process sensitive information unless you have confidence in the entire stack, from the browser and its extensions to the vendor's own security. Understanding how non-human identities work is key, as the agent itself is such an identity, and its credentials are its channel of trust.

Questions people ask

What is the BragJack attack?

BragJack is where a malicious browser extension impersonates the communication channel between a browser's built-in AI assistant and its vendor's servers. By intercepting this trusted traffic, the extension can issue commands to the AI agent, which then executes them with its full privileges, believing they come from Google or Microsoft.

Which browsers and AI assistants were affected?

Researchers disclosed that the attack affected AI assistants in Chromium-based browsers. This included the Gemini Live assistant in Google Chrome, the Copilot assistant in Microsoft Edge, assistants in Opera and Perplexity browsers, and the Claude browser extension. Patches have been released for the major browsers.

How can a simple extension gain so much power?

Browser extensions request permissions to read and modify web traffic. When you grant these, the extension can intercept requests to specific domains, like those of the AI vendor. The AI agent is designed to trust its origin completely, so it cannot detect this interception. The extension's power comes from hijacking the agent's trust, not from its own permissions.

What is the single most important defence?

The most critical step is to ruthlessly audit and restrict browser extensions, especially on work or sensitive devices. In an organisation, enforce a strict allow-list via policy. For personal use, remove any extension you do not actively need. This reduces the attack surface to a minimum, as the exploit requires a malicious or compromised extension to be present.

Close

BragJack exposes a fundamental tension in modern browsing: we add powerful, autonomous agents to our browsers while simultaneously installing third-party extensions that can undermine their security. The attack is a stark lesson in composite trust models. The agent's security is only as strong as the weakest component with access to its communication line. Defending against it requires a shift in perspective—you are not just securing an AI, you are securing the entire runtime environment it depends on.

This pattern of supply chain risk repeats across the agentic ecosystem, from malicious MCP servers to poisoned Python packages. The browser extension is just one vector in a broader set of agentic supply chain threats. Your defence must be architectural: limit agency, segment access, and verify every component in the chain. The age of trusting monolithic applications is over; we now must secure complex, interacting systems where identity can be stolen with a redirected API call.

Sources

  1. Tech Insider: BragJack Attack on AI Browser Agents (opens in a new tab)

Questions people ask

What is the BragJack attack?

BragJack is where a malicious browser extension impersonates the communication channel between a browser's built-in AI assistant and its vendor's servers. By intercepting this trusted traffic, the extension can issue commands to the AI agent, which then executes them with its full privileges, believing they come from Google or Microsoft.

Which browsers and AI assistants were affected?

Researchers disclosed that the attack affected AI assistants in Chromium-based browsers. This included the Gemini Live assistant in Google Chrome, the Copilot assistant in Microsoft Edge, assistants in Opera and Perplexity browsers, and the Claude browser extension. Patches have been released for the major browsers.

How can a simple extension gain so much power?

Browser extensions request permissions to read and modify web traffic. When you grant these, the extension can intercept requests to specific domains, like those of the AI vendor. The AI agent is designed to trust its origin completely, so it cannot detect this interception. The extension's power comes from hijacking the agent's trust, not from its own permissions.

What is the single most important defence?

The most critical step is to ruthlessly audit and restrict browser extensions, especially on work or sensitive devices. In an organisation, enforce a strict allow-list via policy. For personal use, remove any extension you do not actively need. This reduces the attack surface to a minimum, as the exploit requires a malicious or compromised extension to be present.

Ask NEXUS about this article

Get an AI-powered summary, key points, or follow-up questions about BragJack: How a Browser Extension Hijacks Your AI Assistant's Trust, grounded in the essay content and the broader corpus.